The Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.
This was revealed in a joint advisory in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI).
"As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services," they said.
"Other victims include organizations in the medical, education, legal, insurance, technology, and manufacturing industries."
This is an update to a joint report published in March 2025, which said the Medusa ransomware operation had impacted an estimated over 300 critical infrastructure organizations.
The three federal agencies recommended that network defenders secure their networks against the ransomware group's attacks by mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts.
Security teams are also advised to segment networks to block lateral movement after compromise and to block access from untrusted origins to remote services on internal systems.
Active since January 2021
The Medusa ransomware operation surfaced five years ago, in January 2021. Still, the gang's activity only picked up in 2023 after launching the Medusa Blog leak site and began using stolen data as leverage to pressure victims into paying ransoms.
Medusa emerged as a closed ransomware variant, but it evolved into a Ransomware-as-a-service (RaaS) operation and adopted an affiliate model.
... continue reading